You protect the path from an engineer's change to a user's computer, so every delivered component is traceable to an intended source and build. Supply chain is where a lot of otherwise careful security postures quietly fail, and this role exists because we would rather not find that out later.
Open for applications. Starts at: Pilot expansion.
We are taking applications for this role now and building the pipeline for it. The stage above is when the work itself is expected to begin, which is something you deserve to know before you apply rather than after. It is context, not a gate.
Where
In the office together five days a week, in one of our garages, and remote-friendly around your family, arranged one person at a time. We hire across the United States 🇺🇸, India 🇮🇳 and the UAE 🇦🇪.
The work
Build reproducible packaging, dependency inventories, artifact signing, isolated build systems and release provenance. Apply the same discipline to firmware, containers, models and extensions. Design signing-key rotation and recovery from a compromised release credential.
The milestone
In your first 90 days, produce a signed release with a software bill of materials, verifiable provenance and a tested rollback path.
Required
Nice to have
Evidence
Bring practical build-system and release-security experience. Explain the difference between signing an artifact and proving that it was built from an approved source.
Evidence, not credentials. We are describing work you can point at, in whatever form it exists.
The exercise
Design a release response after a dependency is compromised, including how affected users and artifacts are identified.
The package
Indicative pay ranges by market and level are on the compensation page. Plan numbers are confirmed in your offer letter.
Apply
One short form. A person reads every application and you hear back either way. You will get your own link to check where things stand, and you can withdraw or delete your application from it at any time, without an account.